Every ISMS project starts with the same finding. The asset inventory is out of date, incomplete, and full of conflicts. Yet the rules all build on it:
- ISO 27001 A.5.9 requires a full record of information assets.
- BSI IT-Grundschutz builds its whole model on top of it.
- NIS-2 calls for a risk rating for each asset.
If you don't have your inventory under control, you don't have your ISMS under control.
What an "Asset" Means in an ISMS
An asset is not the same as hardware. In an ISMS, it covers:
- Information assets: databases, files, and documents, sorted by classification.
- Software assets: apps, licenses, cloud subscriptions, and open-source libraries (SBOM).
- Hardware assets: servers, notebooks, mobile devices, IoT sensors, and switches.
- Service assets: internal and external services. One example is a mail service as a logical asset, backed by hardware, software, and staff.
- People assets: key people with special knowledge or special rights.
- Supplier assets: critical processors and third parties.
Lifecycle Phases That Come Up in Every Audit
- Buying: purchase with security requirements.
- Running: live use with configuration and patch management.
- Upkeep: regular maintenance and update cycles.
- Retiring: safe data deletion and hardware destruction with a certificate.
A classic audit finding: phase 4 is not documented. Notebooks "vanish" at the end of their life, and proof of data destruction is missing.
What SecTepe.Core Does Differently
- Lifecycle workflow: each change in an asset's state (for example, from running to retiring) starts a workflow. In it, you must upload proof of data deletion.
- Protection needs: for each asset, you rate confidentiality, integrity, and availability on a three-level scale (in line with BSI). The rating passes on to dependent assets on its own.
- Owners: each asset has an owner (who is responsible) and a custodian (who runs it). The audit log records every change.
- Dependency graph: a database server that supports a critical mail service is marked "critical" on its own.
- Auto-discovery: you can add connectors to Active Directory, Hyper-V/vCenter, AWS tags, and Kubernetes namespaces. They fill the inventory half-automatically, so you don't have to type it in.
Links to Other ISMS Modules
An asset with no link to risks, controls, and reviews is just a card in an asset database. SecTepe.Core links it to:
- Risk module: each asset has a risk matrix with likelihood and impact for each threat.
- Control mapping: ISO 27001 controls point to asset classes. For example, A.8.20 network security applies to all network assets.
- Review cycle: a yearly asset review that notifies the owner. See review cycle management.
- BCDR plan: critical assets get an RTO/RPO entry and a linked recovery plan.
- IVDB link: in German statutory health insurance (SHI), procedures from the IVDB are imported as an asset class.
Common Pain Points and How We Solve Them
- "Excel reality": today, 80 % of inventories sit in Excel. Our answer is a CSV/Excel import wizard that spots conflicts.
- "Who owns this?": a workflow forces you to name an owner when you add an asset. No asset goes without one.
- "Stale data": a yearly review cycle escalates if the owner does not react.
- "Scaling": 10,000 assets are no problem in a Postgres table. Bulk actions and tag filters keep the UI easy to use.
Conclusion
Asset management is the least exciting part of an ISMS, but it matters most in an audit. If your inventory is under control, you have done 50 % of the ISMS work. If not, you will fight follow-up findings in every other area at every audit. A platform that links lifecycle, protection needs, owners, and dependencies in one model saves the typical 200 person-hours of audit prep.